• CVE-2024-38517

发布时间: 2024年7月19日

修改时间: 2024年10月9日

概要

Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow vulnerability (when the file is parsed), leading to elevation of privilege.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Local
CVSS评分 N/A 7.8
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity High
User Interaction Required
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4805 rapidjson security update 2025年2月25日

影响产品

产品 状态
KY3.4-5 rapidjson Fixed
KY3.5.2 rapidjson Fixed
KY3.5.3 rapidjson Fixed
V6 rapidjson Fixed